Compliance

Device Control Compliance: USB and Removable Media Requirements

Device control compliance is the enforcement and documentation of policies that govern how removable storage and peripheral devices connect to, interact with, and transfer data across endpoints.

Nivedhitha Damodaran · Product Expert, ManageEngine

Device control compliance is the enforcement and documentation of organizational policies governing how removable storage and peripheral devices connect to, interact with, and transfer data across endpoints. USB drives, external hard disks, optical media, and other removable peripherals represent persistent data-exfiltration and malware-introduction risks. Device-control software helps organizations authorize, restrict, monitor, and document peripheral access in ways that align with applicable regulatory and framework requirements.

Device-control software supports compliance. It does not guarantee it. Compliance depends on written policies, governance processes, risk assessments, documented exceptions, and evidence retained over time.

Most cybersecurity frameworks do not require organizations to disable every USB port. They require organizations to authorize, restrict, protect, monitor, and document the use of removable media according to data sensitivity and risk.

What is device control compliance?

It sits within a broader set of endpoint and data-protection controls:

Endpoint and data-protection control areas related to device control
Control areaPurpose
Device controlControls which peripheral devices can connect
Removable-media managementGoverns media ownership, use, storage, and disposal
EncryptionProtects data stored on permitted media
Endpoint DLPControls which data can be transferred
Malware protectionScans removable media for malicious content

These areas overlap but are not interchangeable. A device-control policy that blocks unauthorized USB devices addresses a different objective than an encryption policy that protects data on permitted ones. Effective compliance programs address each layer.

Which cybersecurity frameworks require USB and removable-media controls?

Several major frameworks include explicit or risk-based requirements for removable-media governance. None universally mandates disabling all USB ports. Applicable obligations depend on the organization's scope, the data it handles, and its risk assessment.

Device-control compliance comparison across major frameworks
FrameworkWho it applies toRelevant requirementWhat the framework expectsSupporting device-control measures
NIST SP 800-171 Rev. 3Organizations handling CUIMedia protection and system-use controlsControl removable-media use and prohibit media without an identifiable ownerDevice allowlisting, serial-number identification, access restrictions, logging
ISO/IEC 27001:2022Organizations operating an ISMSAnnex A.7.10, Storage mediaManage media acquisition, use, transport, storage, and disposalAccess policies, encryption enforcement, activity records
PCI DSS v4.0.1Organizations handling payment-card dataRequirements 9.4 and 5.3.3Protect account-data media and scan removable media when inserted or connectedMedia access restrictions, inventory, malware scanning, audit logs
NIS2Covered essential and important entitiesArticle 21 and Implementing Regulation 2024/2690Apply risk-management measures; covered entities under 2024/2690 face specific removable-media obligationsAuthorization, technical prohibition of unauthorized connections, scanning, logging
DORAEU financial entitiesICT risk-management requirementsProtect ICT assets through proportionate access and security controlsRisk-based peripheral restrictions, logging, exception management
Australian ISMAustralian government systems and relevant organizationsCurrent removable-media controlsAuthorize, register, label, restrict, sanitize, and track removable mediaHardware allowlisting, device records, serial-number controls

The table maps frameworks to supporting implementations. Explicit regulatory mandates differ from risk-based obligations: both types appear in the sections below.

NIST SP 800-171 removable-media requirements

Who must comply with NIST SP 800-171?

NIST SP 800-171 applies to non-federal organizations that process, store, or transmit Controlled Unclassified Information (CUI) on behalf of federal agencies. This includes defense contractors, research institutions, and commercial suppliers operating under federal contracts that reference DFARS or equivalent CUI-protection requirements. Compliance is typically a contractual condition, with CMMC assessments increasingly used to verify it.

What does NIST require for removable media?

NIST SP 800-171 Rev. 3 includes media protection controls requiring organizations to:

  • Restrict or prohibit defined types of system media on system components
  • Prohibit removable system media without an identifiable owner
  • Protect and control portable storage devices containing CUI during transport
  • Sanitize or destroy removable media before disposal or reuse
  • Mark media with necessary CUI markings and distribution limitations

Device-control measures that support NIST compliance

  • Device allowlisting

    Only pre-approved devices, identified by serial number or hardware identifier, are permitted to connect. Media without an identifiable owner is blocked at the endpoint.

  • Access restrictions

    Users and endpoints that do not require removable-media access have it disabled by policy. Access is granted based on role and business need.

  • Connection and activity logging

    Organizations should determine whether removable-media connections and file activity are selected auditable events based on their audit, investigation, and CUI-protection requirements. Where they are, logs capture user identity, device identifier, timestamp, and endpoint.

  • Media sanitization controls

    Policies define how devices must be handled before reuse or disposal. Activity logs provide supporting evidence.

  • Audit evidence

    Assessors reviewing NIST compliance typically examine documented policies, configuration records showing device restrictions, access logs covering the assessment period, exception records, and evidence of periodic policy review.

ISO 27001 USB and removable-media controls

ISO 27001 Annex A.7.10 requirements

ISO/IEC 27001:2022 addresses storage media governance under Annex A.7.10. The control requires organizations to manage storage media across its entire lifecycle — acquisition through use, transport, storage, and disposal — in accordance with the organization's classification and handling requirements. Organizations must establish procedures for the secure handling of media containing sensitive information and ensure disposal renders data unrecoverable.

Does ISO 27001 require USB ports to be blocked?

No. ISO 27001 does not require organizations to disable USB ports universally. The standard requires organizations to select controls appropriate to their risk assessment and document those selections in a Statement of Applicability. Depending on the assessed risk, organizations may block USB access, restrict it to approved devices, or monitor permitted use — provided the rationale is documented and reviewed.

Device-control measures that support ISO 27001

  • Media lifecycle management

    Policies cover acquisition, authorized use, transport, storage, and secure disposal, with records demonstrating each stage is controlled.

  • Authorization and accountability

    Approved media is assigned to specific users or roles. Unapproved media is blocked or flagged.

  • Encryption coordination

    Where media carries sensitive data, organizations can combine device-control restrictions with approved removable-media encryption tools or policies to enforce protection before transfer.

  • Secure disposal

    Policies define sanitization requirements. Logs and disposal records support evidence of compliance.

  • Policy enforcement and review

    Device-control configurations are reviewed at defined intervals and after significant organizational changes. Review records are retained.

PCI DSS removable-media requirements

Which PCI DSS requirements apply to removable media?

PCI DSS v4.0.1 addresses removable media primarily under two requirements:

Requirement 9.4 covers the physical and logical protection of media containing account data. This includes restricting access, maintaining inventories of media, securing media during transport, and ensuring secure destruction when media is no longer needed.

Requirement 5.3.3 requires that anti-malware mechanisms perform automatic scanning or continuous behavioral analysis when removable electronic media is inserted, connected, or mounted to a system — unless the organization documents a risk analysis concluding that the media presents no risk of malware to the cardholder data environment.

Does PCI DSS require USB blocking?

No. PCI DSS does not require organizations to disable USB ports universally. It requires organizations to protect account-data media, maintain controlled access, and scan removable media for malware when connected to in-scope systems where applicable. Organizations that permit removable-media use within their cardholder data environment must implement appropriate controls and document them.

Device-control measures that support PCI DSS

  • Media access restrictions

    Access to removable media is limited to individuals with a documented business need. Controls prevent unauthorized connection to in-scope systems.

  • Media classification and inventory

    All media containing account data is classified, labeled, and tracked. Inventory records are maintained and periodically verified.

  • Restricted access

    User- and device-level controls determine who can connect removable media to cardholder data environment endpoints.

  • Secure destruction

    Policies and records demonstrate that media containing account data is destroyed using methods that render data unrecoverable before disposal. This is typically a process and physical-security control rather than a device-control software function.

  • Malware scanning

    Requirement 5.3.3 applies to anti-malware capabilities. Where removable media is permitted in the CDE, automatic scanning on connection is enforced by endpoint protection software. Device-control software complements this by restricting which devices can connect, reducing the attack surface that scanning must cover.

  • Audit logs

    Connection events, access approvals, and violations are logged with sufficient detail to support forensic review.

NIS2 removable-storage security requirements

How NIS2 applies to removable media

The NIS2 Directive establishes minimum cybersecurity risk-management obligations for essential and important entities operating in the EU. Article 21 requires covered entities to implement security measures proportionate to their risk, including access-control policies, asset management, and incident-prevention measures. Removable-media governance falls within these obligations where it is material to the organization's risk posture.

NIS2 versus Implementing Regulation 2024/2690

Commission Implementing Regulation (EU) 2024/2690 introduces more specific requirements for a defined subset of entities — including DNS providers, TLD registries, cloud services, data centers, content delivery networks, managed service providers, and certain digital service providers. For these entities, Section 12.3 of the implementing regulation specifies explicit removable-media obligations:

  • Establish a removable-media policy governing use across the organization
  • Technically prohibit removable-media connections unless an organizational reason exists
  • Disable automatic execution of content from removable media
  • Scan removable media for malicious code before use
  • Protect portable storage devices during transit and storage
  • Apply cryptographic protection where appropriate to the sensitivity of the data

These requirements apply only to entities within the scope of the implementing regulation, not to every NIS2-covered entity. Organizations should determine their applicable obligations before selecting controls.

Device-control measures that support NIS2

  • Authorization and access control

    Removable-media use is restricted to authorized users and devices. Unapproved connections are blocked and logged.

  • Technical prohibition of unauthorized connections

    Device-control software enforces the implementing regulation's requirement to prohibit connections unless an organizational reason exists, providing the technical layer behind the policy obligation.

  • Autorun/autoplay disabling

    Disabling automatic execution of removable-media content reduces the malware-introduction risk that the implementing regulation addresses. This can be enforced through endpoint configuration management alongside device-control policies.

  • Malware scanning

    The scanning requirement in 2024/2690 is an anti-malware capability. Device-control restrictions reduce the set of devices that require scanning by limiting which media can connect at all.

  • Logging

    Connection and file-transfer activity is logged with retention aligned to incident-response and reporting obligations.

How device control supports DORA compliance

DORA ICT risk-management expectations

The Digital Operational Resilience Act (DORA) applies to EU financial entities — including banks, insurers, investment firms, and payment service providers. Critical ICT third-party providers are subject to a separate EU oversight framework under DORA; their obligations differ from those of the financial entities they serve and should be assessed independently.

DORA requires covered financial entities to implement comprehensive ICT risk-management frameworks covering asset identification, risk assessment, protection measures, detection, response, and recovery. Removable-media governance is not explicitly named as a discrete requirement in DORA's primary text, but DORA's ICT risk-management obligations encompass the protection of ICT assets against unauthorized access, use, and disclosure — which includes peripheral and removable-media attack vectors where they are material to the entity's ICT risk profile.

Applying risk-based peripheral access controls

Financial entities implementing DORA's ICT risk-management framework should assess whether uncontrolled peripheral and removable-media access represents a material risk to their ICT systems. Where it does, proportionate access controls are appropriate. Device-control measures support DORA's protection objectives as a risk-based implementation, not as a direct mandate:

  • Restricting ICT asset access to authorized users and approved devices
  • Generating activity records that support incident detection and investigation
  • Enforcing policies that limit the scope of potential data incidents
  • Enabling documented exception management with audit trails

Evidence financial entities should retain

  • Written removable-media policies reviewed at appropriate intervals
  • Device-control configuration records showing approved and blocked device classes
  • Access approval records for permitted removable media
  • Connection and activity logs for the relevant retention period
  • Exception records including justification, approver, scope, and expiration
  • Evidence of periodic policy review and configuration testing

Australian ISM removable-media controls

Authorization and registration requirements

The Australian Government Information Security Manual (ISM) includes controls governing removable-media use across government systems. The ISM is updated regularly; all claims in this section should be verified against current control identifiers in the version published by the Australian Cyber Security Centre before publication or implementation.

The ISM addresses authorization of removable-media devices for use with specific systems, registration of devices with the organization, and assignment to an identifiable owner. Unregistered or unauthorized media should not be connected to in-scope systems.

Media classification, handling, and sanitization

The ISM requires that removable media be classified and handled in accordance with the information it carries. Sanitization requirements specify that media must be sanitized using approved methods before reuse on systems of lower classification or before disposal.

Device-control measures that support ISM implementation

  • Hardware allowlisting

    Only registered and authorized devices are permitted to connect to in-scope systems. Allowlists enforce this at the driver level.

  • Device records

    A register of approved removable media supports the ISM's ownership and registration expectations.

  • Serial-number controls

    Device-control software can enforce allowlists based on hardware-level identifiers, preventing connection of unregistered media.

  • Activity logging

    Connection and file-transfer activity supports security incident investigation and policy review.

Explicit device-control mandates vs. risk-based requirements

Organizations interpreting framework requirements should distinguish between three types of obligations:

Types of device-control compliance obligations
Requirement typeMeaningTypical response
ExplicitThe framework directly states a media-control obligationImplement and document the stated control
Risk-basedThe organization determines controls based on assessed riskBlock, restrict, or monitor devices according to risk
SupportingA technical control helps satisfy a broader requirementDocument how the control supports the compliance objective

Several factors determine which controls apply:

  • Applicability and scoping

    Framework obligations apply to specific entities, data types, and environments. Scoping analysis must precede control selection.

  • Risk assessments

    Risk-based frameworks require documented risk assessments to justify control choices. A control selected without a supporting risk assessment is difficult to defend to an auditor.

  • Compensating controls

    Where a prescribed control cannot be implemented, frameworks typically allow alternatives that achieve an equivalent objective. These must be documented and approved.

  • Data classification

    The sensitivity of data handled determines which controls are proportionate.

  • Business exceptions

    Legitimate operational requirements may make certain restrictions impractical in specific contexts. Exceptions should be formally requested, reviewed, approved, time-limited, and documented.

Technical device controls used for compliance

The table below maps core device-control capabilities to the risk they address, relevant frameworks, and the evidence they generate. Encryption and malware scanning are complementary controls implemented through separate security tools; they appear where they interact with device-control policy.

Technical device controls mapped to risk, frameworks, and evidence
Technical controlRisk addressedFramework relevanceEvidence generated
Block unauthorized device classesUnrestricted access enabling exfiltration and malware introductionNIST, ISO 27001, PCI DSS, NIS2, DORA, ISMBlocked-connection logs with device class, user, endpoint, timestamp
Allow approved devices by VID, PID, or serial numberUse of unidentifiable or unregistered mediaNIST (identifiable owner), ISM (serial-number registration), ISO 27001 (accountability)Allowlist configuration, approved-device register, connection logs
Enforce read-only accessData exfiltration via write to removable mediaISO 27001, PCI DSS, NIS2, DORARead-only policy configuration, file-activity logs
Restrict file types and transfer sizesTargeted exfiltration; introduction of executable malwareNIS2, DORA, PCI DSSFile-transfer logs, blocked-transfer records
Coordinate with removable-media encryption toolsData exposure from lost or improperly disposed mediaISO 27001, NIST, PCI DSS, ISMEncryption policy records, compliance reports
Grant temporary, time-bound accessUncontrolled exception managementNIST, ISO 27001, PCI DSS, DORARequest and approval records, access-grant and expiration timestamps
Record device connections and file activityInability to detect violations, investigate incidents, or demonstrate enforcementNIST, PCI DSS, NIS2, DORA, ISM, ISO 27001Connection logs, file-transfer logs, violation logs, exportable reports
Alert administrators to policy violationsDelayed detection of active violationsNIS2, DORA, NIST, ISO 27001Alert logs, incident records, response documentation
Scan removable media for malware (anti-malware tool)Malware introduction via removable mediaPCI DSS Req. 5.3.3, NIS2 Reg. 2024/2690, ISMScan records, detection events (requires endpoint protection software)

How to prove device-control compliance to auditors

A written policy is necessary but not sufficient. Auditors expect evidence of continuous enforcement across the assessment period. The following table covers core control objectives and the evidence that supports them.

Device-control audit evidence checklist

Control objectiveEvidence to retain
Unauthorized devices are blockedDevice-control policy and blocked-connection logs
Approved devices are identifiableSerial number, assigned owner, and approval records
Access is appropriately restrictedRead/write permission configurations
Exceptions are controlledRequest, approval, justification, scope, and expiration
Device activity is monitoredConnection, file-transfer, and violation logs
Permitted data is protectedEncryption policy records and compliance reports
Policies remain effectiveReview records, configuration changes, and periodic reports

The gap between "we have a policy" and "we can demonstrate the policy was enforced throughout the period" is a common source of audit findings. Device-control software that generates continuous, exportable logs addresses this gap directly.

Log retention periods should align with the applicable framework's requirements, contractual obligations, and organizational incident response needs. PCI DSS specifically requires audit log retention for at least 12 months, with the most recent three months immediately available. Other frameworks set their own retention expectations; organizations should apply the requirement relevant to each applicable standard rather than assuming a single period covers all obligations.

Device-control compliance checklist

  • Identify all removable-media and peripheral device types used across your environment.
  • Define which users and endpoints require removable-media access, and document the business justification.
  • Block unauthorized device classes by default on all in-scope endpoints.
  • Allow approved devices using unique hardware identifiers (VID, PID, or serial number).
  • Apply read-only access where write access is unnecessary.
  • Coordinate with removable-media encryption tools where sensitive data requires protection in transit.
  • Establish a documented exception workflow with formal request, approval, scope, and expiration.
  • Automatically expire temporary permissions without requiring manual revocation.
  • Record device connections and file transfers with sufficient detail for audit and investigation.
  • Alert administrators to violations in real time or near-real time.
  • Review approved-device inventories at defined intervals and after personnel changes.
  • Retain audit evidence according to applicable framework requirements and organizational retention policies.
  • Test device-control policies across both remote and on-premises endpoints to confirm consistent enforcement.

How Device Control Plus supports compliance

Device Control Plus provides centralized control over peripheral and removable-media access across organizational endpoints, enabling IT and security teams to define, enforce, and document device policies at the organizational, group, or endpoint level.

  • Centralized peripheral access policies

    Policies are defined once and applied consistently across managed endpoints, including remote devices, reducing configuration drift and unmanaged exceptions.

  • Device-class and device-level restrictions

    Administrators can block entire device classes or restrict access to specific approved devices, applying the appropriate level of granularity for the endpoint's risk profile.

  • VID, PID, and serial-number controls

    Allowlists based on hardware-level identifiers ensure only registered, approved devices can connect. This directly addresses the NIST requirement to prohibit use of media without an identifiable owner and supports ISM serial-number registration expectations.

  • Read-only access enforcement

    Read-only policies can be applied at the user, group, or endpoint level, limiting exfiltration risk while preserving workflows that depend on receiving data from external media.

  • Temporary access management

    Controlled, time-bound access grants are documented automatically, with expiration enforced without manual follow-up, supporting exception governance requirements across frameworks.

  • File-transfer monitoring

    File-level activity on connected removable media is recorded, including file name, type, direction, user, and endpoint, providing the continuous enforcement evidence auditors expect.

  • Device activity reports

    Exportable reports provide audit-ready summaries of device connections, policy violations, approved-device activity, and exception history across the assessment period.

  • Policy-violation visibility

    Administrators are alerted to unauthorized connection attempts and blocked transfers, supporting the detection and response capabilities expected under NIS2 and DORA.

For encryption of data on permitted media and malware scanning of removable media, Device Control Plus works alongside dedicated encryption and endpoint protection tools. Effective removable-media compliance programs typically combine controls from multiple product categories.